Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Problems with IPv6 firewall and connecting devices

I have a 3rd generation Time Capsule....Over a year ago, I started having a lot of problems with wi-fi devices dropping from the network. At the time, I thought it was because my neighborhood was overly saturated with wi-fi signals. I've had much better luck with 5ghz networks, but some of the older devices in the house don't support 5GHz wifi.


Anyway, I just resurrected a couple of older machines - an old smartphone (android) and an old laptop (windows 7). Neither device was able to connect to the network at all. Both indicated authentication problems.


I started trying a couple of things with the settings on the time capsule, and it turns out that removing the IPv6 firewall (unchecking 'Block IPv6 incoming connections' under Network > Network Options) seems to allow these devices to connect. I have tested it, and everytime I re-enable the firewall, the devices stop connecting.


I have two questions:


1) Does this behavior make sense to anyone?

2) Is it a huge security risk to leave 'Block IPv6 incoming connections' unchecked?


As some additional information, I generally haven't had many problems with newer devices connecting (even to the 2.4GHz network). Also, if it's helpful at all, the TC is connected to a cable modem (RCN is the provider).


Any insight/assistance would be greatly appreciated. Thanks!!!

Posted on Jul 30, 2015 7:55 PM

Reply
Question marked as Best reply

Posted on Jul 30, 2015 8:40 PM

Does RCN actually support IPv6?? Check on the windows laptop for IP.. (that means opening a dos window and typing arcane dos commands like ipconfig /all)


If you are getting IPv6 then your computer maybe directly accessible by internet .. which is not really a big issue as long as you have windows firewall turned on.. it should also get IPv4 address.


It also can be caused by a number of factors like gen3 TC used a Maxell wireless card.. and android phone is probably using atheros and win7 laptop maybe using Intel.. wireless is never very happy across brands.. but Apple check their drivers all work.. other brands face a million zillion routers on the market and it is impossible.


What I would suggest is to make all names in the TC simple, short, pure alphanumeric and no spaces.


Passwords also mixed case and numbers.. but pure alphanumerics.


Test with no security (block IPv6 on.. but I doubt that is real issue).


2) Is it a huge security risk to leave 'Block IPv6 incoming connections' unchecked?

Not to windows.. as long as the firewall is on..


Android phone I cannot really speak to.. if it is getting IPv6 public IP and is accessible it could be a problem but I sort of doubt it.


If you post more details on the TC setup I might be able to help some more.. A few screenshots of settings could help.

3 replies
Question marked as Best reply

Jul 30, 2015 8:40 PM in response to cseshag

Does RCN actually support IPv6?? Check on the windows laptop for IP.. (that means opening a dos window and typing arcane dos commands like ipconfig /all)


If you are getting IPv6 then your computer maybe directly accessible by internet .. which is not really a big issue as long as you have windows firewall turned on.. it should also get IPv4 address.


It also can be caused by a number of factors like gen3 TC used a Maxell wireless card.. and android phone is probably using atheros and win7 laptop maybe using Intel.. wireless is never very happy across brands.. but Apple check their drivers all work.. other brands face a million zillion routers on the market and it is impossible.


What I would suggest is to make all names in the TC simple, short, pure alphanumeric and no spaces.


Passwords also mixed case and numbers.. but pure alphanumerics.


Test with no security (block IPv6 on.. but I doubt that is real issue).


2) Is it a huge security risk to leave 'Block IPv6 incoming connections' unchecked?

Not to windows.. as long as the firewall is on..


Android phone I cannot really speak to.. if it is getting IPv6 public IP and is accessible it could be a problem but I sort of doubt it.


If you post more details on the TC setup I might be able to help some more.. A few screenshots of settings could help.

Jul 31, 2015 3:28 AM in response to LaPastenague

Thanks for the response and assistance!


RCN does not seem to support IPv6 at this point, and all the machines internally have IPv4 addresses only. I have snapped a few screenshots of my settings for the TC if this helps. The first is a shot of the Network Tab:


User uploaded file


Next is a shot of the Internet Options submenu. I had always just left these settings as the default:


User uploaded file


Here is a shot of the 'Network' tab:


User uploaded file


And lastly, the 'Network Options' submenu where I have unchecked the 'Block incoming IPv6 connections':


User uploaded file


As far as whether or not the IPv6 firewall is the source of the problem, I have now done the test several times where this is the only factor that I change, I restart/update the router and if this box is checked, these devices simply will not connect to the wi-fi, but as soon as I uncheck this box, they connect with no problems. I don't really understand why this would be the case, but if you have any further insight, please let me know!


Thanks again for your help!

Jul 31, 2015 3:26 PM in response to cseshag

I am not able at this point to reproduce the problem.. which is usually the first step in figuring out how or why your solution works..


Using older OS and Gen5 AE .. that option simply doesn't exist.


User uploaded file


And I have no issues with non-apple devices connecting.. and never had issues.. due to sticking with SMB naming rules.. and usually fixed channels.


BTW a big thanks for posting.. this is not unusual problem.. and I will suggest to people this as a solution now. Lets see if it is reproducible.

Problems with IPv6 firewall and connecting devices

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.